StackRadar

CVE-2025-9086

High

Advisory

Published 10 Sept 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.014
71st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
579
of 17,787 indexed, latest versions
Container images
632
deployed by those charts
Fix available
3 of 3
affected packages

Red Hat Security Advisory: curl security update

Carried by container images the latest versions of 579 of 17,787 indexed charts deploy, on 632 images.

Affected packageAffected versionsFixed inImages
curldeb1:8.14.1-2+deb13u3+e1, 7.74.0-1.3+b1, 7.74.0-1.3+deb11u1, 7.74.0-1.3+deb11u2+12 more7.74.0-1.3+deb11u16, 8.14.1-2+deb13u1, 8.14.1-2+e1, 8.14.1-2ubuntu1.1291
curlapk8.14.0-r2, 8.14.1-r0, 8.14.1-r18.14.1-r235
curlrpm7.61.1-8.el8, 7.61.1-11.el8, 7.61.1-12.el8, 7.61.1-12.el8_2.4+34 more0:7.61.1-34.el8_10.9, 0:7.76.1-23.el9_2.8, 0:7.76.1-29.el9_4.3, 0:7.76.1-31.el9_6.2+2 more306
OSV records
ALPINE-CVE-2025-9086DEBIAN-CVE-2025-9086UBUNTU-CVE-2025-9086RHSA-2025:23043RHSA-2025:23125RHSA-2025:23127RHSA-2025:23383RHSA-2026:1350RHSA-2026:1825RLSA-2025:23383RLSA-2026:1350DLA-4432-1ECHO-6a25-e091-8eb3
Also known as
USN-8062-1

Charts affected

579 by stars
ChartLatestAffected imagesRadar Score
todolist-charttodolist-chart0.1.71 of 10See more

todolist-chart todolist-chart 0.1.7

1 of the 10 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
erenozcan17/react_frontend:v4.56e1b14973f9b
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

6,974
token-servertoken-server1.0.91 of 1See more

token-server token-server 1.0.9

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
udhos/token-server:1.0.9728013f2fac1
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

1,245
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

12,454
synapsetranhailongVerified publisher0.1.01 of 2See more

synapse tranhailong 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
matrixdotorg/synapse:v1.78.0def97fd537d8
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

3,164
zookeepertwomartensVerified publisher0.2.21 of 1See more

zookeeper twomartens 0.2.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
confluentinc/cp-zookeeper:latest7610a50b13e7
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9

Open the chart page →

1,733
jupyterhubuninettsigma21.6.01 of 5See more

jupyterhub uninettsigma2 1.6.0

1 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/nird-toolkit/jupyterhub-server:20221215-e6aa80ecae8c0622533
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

8,370
miniouninettsigma21.2.01 of 1See more

minio uninettsigma2 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
sigma2as/minio:20240306-3a2e4f5c284ead9ec3e
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9

Open the chart page →

4,960
simple-prima-notavcnngrVerified publisher0.5.31 of 4See more

simple-prima-nota vcnngr 0.5.3

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vcnngr/pnfrontend:latest4e4979ab8c41
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

4,769
velero-notificationsvelero-notifications1.1.01 of 1See more

velero-notifications velero-notifications 1.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/simoncaron/velero-notifications:1.0.0d058963d4de7
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,285
n8nvictorlane1.0.181 of 1See more

n8n victorlane 1.0.18

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
n8nio/n8n:1.115.1ed16e560c40e
curl@8.14.1-r1
8.14.1-r2

Open the chart page →

6,470
vinyl-lib-chartvinyl-libVerified publisher0.1.01 of 1See more

vinyl-lib-chart vinyl-lib 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kporwit/vinyl_lib_app:v0.1.1217de0302218
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

3,392
resultappvoting-app-helm-charts-repoVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

1,263
voteappvoting-app-helm-charts-repoVerified publisher1.0.02 of 5See more

voteapp voting-app-helm-charts-repo 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
kodekloud/examplevotingapp_vote:v13a856afb02a3
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

8,287
resultappvoting-app-helm-charts-repo-cloudVerified publisher1.0.01 of 1See more

resultapp voting-app-helm-charts-repo-cloud 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

1,263
voteappvoting-app-helm-charts-repo-cloudVerified publisher1.0.02 of 5See more

voteapp voting-app-helm-charts-repo-cloud 1.0.0

2 of the 5 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
kodekloud/examplevotingapp_result:v1e510023fdf38
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16
kodekloud/examplevotingapp_vote:v13a856afb02a3
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

8,287
apiwbstack0.36.01 of 1See more

api wbstack 0.36.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/wbstack/api:8x.9.11eee94f9f7a53
curl@7.74.0-1.3+deb11u3
7.74.0-1.3+deb11u16

Open the chart page →

2,019
mediawikiwbstack0.14.01 of 1See more

mediawiki wbstack 0.14.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/wbstack/mediawiki:1.37-7.4-20220621-fp-beta-0c3012c8a34b4
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

2,132
drillwearefrank1.3.62 of 3See more

drill wearefrank 1.3.6

2 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16
bitnamilegacy/zookeeper:3.9.0-debian-11-r1110ed1ea3c8d1
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

9,399
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9

Open the chart page →

28,699
webresourcecataloguswebresourcecatalogus1.1.01 of 4See more

webresourcecatalogus webresourcecatalogus 1.1.0

1 of the 4 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
ghcr.io/conductionnl/webresourcecatalogus-nginx:latest6de60c83128d
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

7,552
miniowenerme8.0.101 of 1See more

minio wenerme 8.0.10

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2021-02-14T04-01-33Zbd11edda91f3
curl@7.61.1-14.el8_3.1
0:7.61.1-34.el8_10.9

Open the chart page →

6,915
minio-standalonewenerme1.0.21 of 1See more

minio-standalone wenerme 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
minio/minio:RELEASE.2022-01-04T07-41-07Z1484c87239ea
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

6,138
wexa-studiowexa-studio1.2.03 of 15See more

wexa-studio wexa-studio 1.2.0

3 of the 15 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
temporalio/admin-tools:1.29.1-tctl-1.18.4-cli-1.5.0a3a52e6ca122
curl@8.14.1-r0
8.14.1-r2
temporalio/server:1.29.1c1e3326b2ce1
curl@8.14.1-r0
8.14.1-r2
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9

Open the chart page →

14,618
vaultwardenwitcom-gmbh0.2.01 of 2See more

vaultwarden witcom-gmbh 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
vaultwarden/server:1.25.239f34c5159a2
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

1,585
wp-gats-helmwordpress-gatsby0.0.11 of 3See more

wp-gats-helm wordpress-gatsby 0.0.1

1 of the 3 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
library/wordpress:6.0.0-php8.0-apache277c6c25980f
curl@7.74.0-1.3+deb11u1
7.74.0-1.3+deb11u16

Open the chart page →

2,021
workshop-pipelinesworkshop-pipelines0.1.61 of 2See more

workshop-pipelines workshop-pipelines 0.1.6

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9

Open the chart page →

11,592
keycloakxzaks2.2.01 of 1See more

keycloakx zaks 2.2.0

1 of the 1 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9

Open the chart page →

6,016
enterprise-gatewayzeet3.2.21 of 2See more

enterprise-gateway zeet 3.2.2

1 of the 2 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
elyra/kernel-image-puller:3.2.2c922f1f1646a
curl@7.74.0-1.3+deb11u7
7.74.0-1.3+deb11u16

Open the chart page →

1,838
posthogzeet0.23.21 of 9See more

posthog zeet 0.23.2

1 of the 9 container images this version deploys carry CVE-2025-9086.

Container imageDigestPackageFixed in
altinity/clickhouse-operator:0.19.07a85f522c5bc
curl@7.61.1-25.el8_7.3
0:7.61.1-34.el8_10.9

Open the chart page →

3,697

Container images carrying it

632 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/flomesh/fsm-bootstrap-ubi8:0.1.8-ubi.6e6d7afb1a4bf
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
1
quay.io/flomesh/fsm-ingress-pipy-ubi8:0.1.8-ubi.6fce990dece01
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
1
quay.io/flomesh/fsm-manager-ubi8:0.1.8-ubi.63590af73f65a
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
1
quay.io/flomesh/osm-edge-bootstrap-ubi8:1.2.1e048bc7a17c2
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
1
quay.io/flomesh/osm-edge-controller-ubi8:1.2.1674f45865af1
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
1
quay.io/flomesh/osm-edge-crds-ubi8:1.2.1c3bc5e7a70e6
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
1
quay.io/flomesh/osm-edge-injector-ubi8:1.2.18e9c39c34e89
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
1
quay.io/flomesh/osm-edge-preinstall-ubi8:1.2.1f94282a9cfec
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
1
quay.io/flomesh/pipy-repo-ubi8:0.70.0-469912fdf6c183
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
1
quay.io/flomesh/pipy-ubi8:0.50.0-8824352dca6672
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
1
quay.io/flomesh/pipy-ubi8:0.70.0-4635d87a381432
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
1
quay.io/flomesh/toolbox-ubi8:1.2.01f5e3161cb84
curl@7.61.1-34.el8
0:7.61.1-34.el8_10.9
1
quay.io/galexrt/dellhw_exporter:v2.0.0-rc.18a1361fa38c1
curl@7.76.1-29.el9_4.1
0:7.76.1-35.el9_7.3
1
quay.io/groundcover/tools:20260719b705e0cbe171
curl@1:8.14.1-2+deb13u3+e1
8.14.1-2+e1
1
quay.io/hpestorage/cosi-driver:v2.0.0a4d2667f2b6e
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
1
quay.io/hpestorage/filex-csi-driver:2.6.4b7f960bbf472
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
1
quay.io/hpestorage/filex-csi-init:2.6.42d867eefb233
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
curl@7.61.1-12.el8
0:7.61.1-34.el8_10.9
1
quay.io/icdh/core-dump-handler:v9.0.0cc79b9e2a1c8
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
1
quay.io/jupyterhub/k8s-hub:3.2.12528c6e57587
curl@7.74.0-1.3+deb11u10
7.74.0-1.3+deb11u16
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
curl@7.61.1-18.el8
0:7.61.1-34.el8_10.9
1
quay.io/keycloak/keycloak:20.0.18830f76112b6
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
1
quay.io/keycloak/keycloak:20.0.3b8f2a453a17a
curl@7.61.1-25.el8_7.1
0:7.61.1-34.el8_10.9
1
quay.io/keycloak/keycloak-operator:19.0.3-legacy09d52508fee9
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
1
quay.io/keycloak/keycloak-operator:19.0.2-legacy15fa0ed662b1
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
1
quay.io/keycloak/keycloak-operator:18.0.0-legacy36ce77526145
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
1
quay.io/keycloak/keycloak-operator:20.0.2b1710745fa64
curl@7.61.1-25.el8
0:7.61.1-34.el8_10.9
1
quay.io/konveyor/move2kube-ui:latestec6ab507c5da
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9
1
quay.io/kubevirt/kubemacpool:v0.45.0eebb65b8a12c
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
1
quay.io/manusa/kubernetes_mcp_server:v0.0.47150f76e844d9
curl@7.76.1-31.el9
0:7.76.1-31.el9_6.2
1
quay.io/maximilianopizarro/neuralbank-backend:latesta53899fcfc01
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
1
quay.io/maximilianopizarro/neuralbank-frontend:latest5f4572ef6d6f
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
1
quay.io/maximilianopizarro/neuroface-frontend:v1.4.1841b70cd1424
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
1
quay.io/maximilianopizarro/neuroface-frontend:latestdcf24040cc77
curl@7.76.1-34.el9
0:7.76.1-35.el9_7.3
1
quay.io/maximilianopizarro/nfl-api-bills:1.0.1b596a4687bb0
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
1
quay.io/maximilianopizarro/nfl-wallet-api-customers:1.0.1d50c80a85b35
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
1
quay.io/maximilianopizarro/nfl-wallet-api-raiders:1.0.1f9c71dc2bc5f
curl@7.61.1-34.el8_10.2
0:7.61.1-34.el8_10.9
1
quay.io/maximilianopizarro/openshift-integration-operator:v0.8.2d6fc43ac802e
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
1
quay.io/maximilianopizarro/showroom-docs-mcp:latest1a6eff92827a
curl@7.76.1-31.el9
0:7.76.1-35.el9_7.3
1
quay.io/maximilianopizarro/workshop-pipelines:lateste383ba3e0966
curl@7.61.1-22.el8
0:7.61.1-34.el8_10.9
1
quay.io/mcouliba/quarkus-serverless:1.0c2851757eca4
curl@7.61.1-11.el8
0:7.61.1-34.el8_10.9
1
quay.io/minio/directpv:v4.0.84560083eb77d
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
1
quay.io/minio/mc:RELEASE.2022-10-20T23-26-33Z50ee58bc9770
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
1
quay.io/minio/mc:RELEASE.2022-09-16T09-16-47Z546a8b52d7b0
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
1
quay.io/minio/minio:RELEASE.2022-09-17T00-09-45Zc3d20bc2ea08
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
1
quay.io/minio/minio:RELEASE.2022-10-24T18-35-07Zd853057f2800
curl@7.61.1-22.el8_6.4
0:7.61.1-34.el8_10.9
1
quay.io/mittwald/brudi-operator:v0.2.3edb322094359
curl@7.61.1-30.el8_8.3
0:7.61.1-34.el8_10.9
1
quay.io/mongodb/mongodb-enterprise-operator-ubi:1.33.0b05101723412
curl@7.76.1-31.el9_6.1
0:7.76.1-31.el9_6.2
1
quay.io/mongodb/mongodb-kubernetes-operator:0.3.0107a7c73af59
curl@7.61.1-14.el8
0:7.61.1-34.el8_10.9
1
quay.io/mongodb/mongodb-kubernetes-operator:0.9.05ee4bd681085
curl@7.61.1-34.el8_10.3
0:7.61.1-34.el8_10.9
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.